CVE-2013-1667: important rehashing flaw

Chisel chisel at chizography.net
Wed Mar 13 09:50:56 GMT 2013


On Tue, Mar 12, 2013 at 8:58 AM, Leo Lapworth <leo at cuckoo.org> wrote:
> All updated now

Thanks for doing this makes my prep-work much easier at $work.

I've just stumbled across http://www.cpan.org/src/README.html which says:

Latest releases in each branch of Perl

Major  Version  Type  Released  Download
5.14  5.14.4  Devel  2013-03-07  perl-5.14.4-RC2.tar.gz
5.16  5.16.3  Maint  2013-03-11  perl-5.16.3.tar.gz
5.14  5.14.4  Maint  2013-03-10  perl-5.14.4.tar.gz


To me it looks odd having the RC2 there ... should that be dropped
until there is (another) release candidate?

--
Chisel
e: chisel at chizography.net
w: http://chizography.net


More information about the london.pm mailing list